Security that
demonstrably works.

Independent IT security audits for mid-sized companies — with documented proof, not an opinion.

30,000German companies fall under NIS2
€10mor 2% of turnover — maximum fine
from €2,450Fixed price, known in advance

Most gaps are not
missing controls.

They are controls that were installed, have counted as done for years — and would have achieved nothing in a real incident.

We have a firewall.

But is it in test mode? That is exactly what we found — logging everything, blocking nothing.

We have backups.

But can they be restored? Copying databases while they run produces files that often cannot be loaded back.

We delete after 14 days.

But does every system? Secondary analytics often keep accumulating for years — a GDPR problem.

NIS2

A law most companies
do not know applies to them.

NIS2 is the EU cybersecurity directive. In Germany it has been law since 6 December 2025 — with no transition period.

It requires demonstrable risk management across ten areas — including backup management, access control, multi-factor authentication and supply chain security. On top of that comes mandatory reporting: significant incidents notified within 24 hours, reported within 72 hours. Management is personally liable for implementation.

30,000

affected companies in Germany — up from around 4,500

€10m

or 2% of worldwide annual turnover as the maximum fine

0 days

transition period. Obligations applied from publication

Does it apply to your company?

1. Does your company have at least 50 staff, or more than €10m annual turnover?
2. Does your company operate in one of the 18 covered sectors? Energy · Transport · Banking · Financial markets · Health · Drinking water · Waste water · Digital infrastructure · ICT service management · Public administration · Space · Post and courier · Waste management · Chemicals · Food · Manufacturing · Digital providers · Research
3. Do you supply companies that might fall under NIS2? Through the supply chain requirements, affected companies pass security obligations on to their suppliers — contractually.

This assessment is indicative and does not replace legal advice. Your answers are neither transmitted nor stored — the evaluation happens in your browser.

Services

Six areas.
Each with a verifiable result.

01Infrastructure security auditFull examination

Servers, services and networks in context: what is reachable from outside, what may talk to what internally, where controls only appear to work. The result is an action plan prioritised by risk, with effort estimates.

02Backup and restore verificationOur core method

We actually restore your backup — into an isolated environment with no network access, never touching production — and compare the contents against the original.

You receive written confirmation that recovery is possible. A backup that has never been restored is an assumption.

03NIS2 readiness analysisScope & gaps

Applicability assessment, gap analysis against the ten required risk-management areas, a reporting process for the 24- and 72-hour deadlines, and documentation for the board. Specific to your company, not a template.

04Container and network segmentationWithout downtime

If every service shares one network, a single compromised web application reaches everything: other databases, backups, monitoring. We separate them — step by step, each step individually verified and reversible, without interrupting operations.

05Logging and retention reviewGDPR

IP addresses are personal data. We check whether your retention limits apply everywhere — including analytics databases and rotated logs — and implement retention that preserves statistics while removing the personal data.

06Ongoing supportCancellable monthly

Intrusion detection maintained, updates applied, logs reviewed, a short monthly report. For companies without their own security team. No annual lock-in.

Evidence

Findings from
a real audit.

The subject was a company within our own group: an online shop with payment processing, grown over several years. Same scope and rigour as any client engagement.

0 of 209 login attempts blocked

The firewall was blocking nothing

It had been in observation mode for months. The configuration was correct — a single switch was set to "log only". Today it enforces: from the seventh attempt per minute, requests are refused.

172 tables demonstrably restored after the fix

The offsite backup held no usable database

It captured live database files instead of a consistent dump. Such copies frequently cannot be loaded back. After correcting it we proved recovery — identical to the original.

7 open paths inward, now closed

Everything was reachable from the web service

The second website's database, the backup store, monitoring and intrusion detection — all directly reachable from the public-facing application. One break-in would have sufficed. Today that service reaches two systems.

688 days of IP addresses stored — policy said 14

An analytics database never deleted

2.9m requests, roughly 78,000 distinct IP addresses. Resolved without losing the statistics: daily figures preserved, personal data removed. Afterwards 5,204 addresses instead of 77,925.

Why we may show this. Because the client belongs to our own group and consented to publication. Client reports remain confidential, of course — this example instead shows what we look for, and what a finding looks like with us: a measurement, a cause, and documented remediation.

Network separation

One finding, made visible.

On the left, what we found. On the right, the same systems after separation — without a minute of downtime.

Network before and after separation Before, the website reached all eight systems directly. Afterwards it reaches only its own database and the firewall; backup, invoice archive and analytics sit in separate zones. Before One network. Everyone reaches everyone. Website (public) Own database Second website Backup store Invoice archive Analytics Intrusion detection After Separate zones. Only necessary paths. Website zone Website Own database Firewall Backup — no internet Backup store Invoices — no internet Invoice archive Monitoring — separated Analytics Intrusion detection Network before and after separation Stacked layout for narrow screens. Before One network. Everyone reaches everyone. Website (public) Own databaseSecond websiteBackup storeInvoice archiveAnalyticsIntrusion detection One break-in here reaches everything. After Separate zones. Only necessary paths. Website zone Website Own database Firewall Backup — no internet Backup store Invoices — no internet Invoice archive Monitoring — separated Analytics Intrusion detection

What this means in practice

Before, a single break-in through the website would have reached customer data, invoices and backups. The website is the most attacked point a company has — and it was the point with the most access.

How we do it

Step by step on the running system: each service first added to its new zone, verified, and only then removed from the old one. Every step individually reversible. Downtime in this case: none.

Pricing

Fixed price. Known in advance.

Security consulting is normally billed by the day with an open end. We name the price up front and hold it.

Baseline Check

A first defensible status report.

€2,450

net, one-off · approx. 1 week

  • External attack surface
  • Server and service configuration
  • Encryption and certificates
  • Backup concept reviewed
  • Report prioritised by risk
  • Findings call
Enquire
Most chosen

Infrastructure Audit

For companies running their own servers or containers.

€5,900

net, one-off · approx. 2–3 weeks

  • Everything in the Baseline Check
  • Real restore test
  • Network and container segmentation
  • Access rights and permissions
  • Logging and retention
  • Intrusion detection tested for effectiveness
  • Re-check after 30 days
Enquire

NIS2 & Hardening

For companies within the scope of NIS2.

from €12,500

net · scope agreed after the intro call

  • Everything in the Infrastructure Audit
  • Applicability assessment, documented
  • Gap analysis across all ten NIS2 areas
  • Reporting process, 24 / 72 hours
  • Supply chain
  • Policies and evidence
  • Board-level presentation
Enquire
Ongoing supportfrom €490 / month

Intrusion detection maintained, updates applied, logs reviewed, short monthly report. With a quarterly mini-audit from €890 / month. Cancellable monthly.

Individual work€1,290 / day

Implementing fixes, incident support, a second opinion on an existing report, or support during a certification.

If we find nothing significantYou still get the report

We will tell you — and you receive the report including evidence of what was tested. An audit with no critical findings is a good outcome.

Process

Five steps.

01

Intro call

30 minutes, free. We establish scope and applicability. Not a sales call.

02

Proposal

Fixed price, fixed scope, confidentiality agreement and written authorisation.

03

Audit

On the live system, in reversible steps. Critical findings reported immediately.

04

Report

A summary for management, a technical section with evidence for your IT team.

05

Re-check

Implementation on request. After 30 days we document that the gaps are closed.

About us

We don't only advise.
We operate.

Leaf Invest is an international team based in Hamburg, Germany. The group includes its own production systems: an online shop with payment processing, a legally compliant invoice archive, and servers that are attacked daily.

That shapes how we work. We know the situation where a change stops operations at night — from our own responsibility, not from a case study. So we change things in small steps, verify each one, and always keep a way back. You speak directly with the person auditing.

What we deliberately don't doNo vendor commission

We sell no software and take no commission from vendors. Our recommendation therefore does not depend on what we earn from it. If the right answer is "change one setting", that is what we will say.

This websiteNo cookies, no tracking

No cookies, no external fonts, no analytics. That is why you see no consent banner. For a company advising on data protection, we consider that the bare minimum.

ConfidentialityProcessed in Germany

A confidentiality agreement before any access. Credentials only as long and as broadly as necessary, then verifiably deleted. Reports delivered encrypted. Processing and storage exclusively in Germany.

Questions

Frequently asked.

What does an audit cost?

Baseline Check €2,450, Infrastructure Audit €5,900, NIS2 package from €12,500, all net. The price is fixed before we begin. Individual work €1,290 net per day. That places us mid-market.

Does NIS2 apply to my company?

The German implementing act has applied since 6 December 2025 — with no transition period. It covers companies with 50+ staff or €10m turnover across 18 sectors, an estimated 30,000 in Germany. Suppliers are pulled in through the supply chain requirements.

We assess this in the free intro call. If you are not in scope, we will say so.

How is this different from a penetration test?

A penetration test looks for ways in. That is useful and we do it too. But it does not answer the second question: do the controls you already pay for work?

Does the firewall really block? Can the backup be restored? Do retention limits actually delete? That is where the most uncomfortable findings are.

Will you need to interrupt operations?

Normally not. We work on the running system in small, individually verifiable and reversible steps. Where a brief interruption is unavoidable, we agree the window in advance.

Do you work outside the EU?

Yes. For business customers the place of supply for VAT purposes is the customer's country. Within the EU, with a valid VAT identification number, we invoice under the reverse charge procedure; outside the EU without German VAT.

We consult in German, English and Turkish.

How quickly can you start?

An intro call usually within days, the start of an audit typically in two to four weeks. For an active incident we try to free capacity at short notice.

Contact

Book an intro call.

30 minutes, free. Afterwards you will know whether NIS2 applies to you and where your largest gaps probably are.

This form opens your own email program with the details. No data is transmitted to any third party.